2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-42668CRITICAL9.8A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter in the my_cla...
CVE-2021-42667CRITICAL9.8A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-manag...
CVE-2021-42666HIGH8.8A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to quiz_quest...
CVE-2021-42665CRITICAL9.8An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of inde...
CVE-2021-42664MEDIUM5.4A Stored Cross Site Scripting (XSS) Vulneraibiilty exists in Sourcecodester Engineers Online Portal in PHP via the (1) Q...
CVE-2021-42663MEDIUM4.3An HTML injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via th...
CVE-2021-42662MEDIUM5.4A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Event Booking and Reservation System i...
CVE-2021-26844MEDIUM5.4A cross-site scripting (XSS) vulnerability in Power Admin PA Server Monitor 8.2.1.1 allows remote attackers to inject ar...
CVE-2021-42237CRITICAL9.8Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it...
CVE-2021-25509HIGH7.1A missing input validation in Samsung Flow Windows application prior to Version 4.8.5.0 allows attackers to overwrite ab...
CVE-2021-25508CRITICAL9.8Improper privilege management vulnerability in API Key used in SmartThings prior to 1.7.73.22 allows an attacker to abus...
CVE-2021-25507MEDIUM5.7Improper authorization vulnerability in Samsung Flow mobile application prior to 4.8.03.5 allows Samsung Flow PC applica...
CVE-2021-25506MEDIUM5.5Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider...
CVE-2021-25505HIGH7.8Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is un...
CVE-2021-25504MEDIUM4Intent redirection vulnerability in Group Sharing prior to 10.8.03.2 allows attacker to access contact information.
CVE-2021-25503MEDIUM6.7Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to arbitrary code execu...
CVE-2021-25502MEDIUM5.5A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows ...
CVE-2021-25501LOW3.3An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 al...
CVE-2021-25500MEDIUM4.4A missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrite TZASC allowing TEE...
CVE-2021-39913MEDIUM6.7Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versi...
CVE-2021-39912MEDIUM5.3A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images w...
CVE-2021-39911MEDIUM4.3An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting ...
CVE-2021-39909MEDIUM5.3Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 b...
CVE-2021-39907MEDIUM5.3A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from...
CVE-2021-39906MEDIUM6.1Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaSc...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now